Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2612▼ 295 respecto a la semana anterior
Críticas / altas1346▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.35%—ContinuwuityAIConduitAIGrapevineAITuwunelAI2/2/202617/6/2026
continuwuity is a Matrix homeserver written in Rust. This vulnerability allows an attacker with a malicious remote server to cause the local server to sign an arbitrary event upon user interaction. Upon a user account leaving a room (rejecting an invite), joining a room or knocking on a room, the victim server may ask…
AplazadaCrítica (9.9)0.59%—ConduitAIContinuwuityAIGrapevineAITuwunelAI23/12/202517/6/2026
Conduit is a chat server powered by Matrix. A vulnerability that affects a number of Conduit-derived homeservers allows a remote, unauthenticated attacker to force the target server to cryptographically sign arbitrary membership events. Affected products include Conduit prior to version 0.10.10, continuwuity prior to…
AnalizadaMedia (6.1)0.28%—Aimeos Grapesjs CMS2/12/202517/6/2026
The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8, Javascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. This…
AplazadaAlta (8.8)0.42%—GrapesjsAI2/12/202517/6/2026
Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted. ImpactIf the media folder is not restricted from running files this can lead to a remote code execution.
AplazadaAlta (8.8)0.24%—GradleAINet.rubygrapefruit Native-platformAI25/2/202517/6/2026
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. This library initialization could be vulnerable to a local…
ModificadaAlta (8.8)0.27%—Marketingrapel Mkrapel Regiones Y Ciudades DE Chile Para WC18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Marketing Rapel MkRapel Regiones y Ciudades de Chile para WC.This issue affects MkRapel Regiones y Ciudades de Chile para WC: from n/a through 4.3.0.
ModificadaMedia (6.1)0.77%—Grapesjs25/7/202217/6/2026
The package grapesjs before 0.19.5 are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the class name in Selector Manager.
ModificadaMedia (6.1)1.4%—Ruby-grape Grape5/7/201817/6/2026
ruby-grape ruby gem suffers from a cross-site scripting (XSS) vulnerability via "format" parameter.
ModificadaAlta (7.5)3.7%—Erik Michaels-ober Multi XMLGrape Project Grape25/4/201316/6/2026
multi_xml gem 0.5.2 for Ruby, as used in Grape before 0.2.6 and possibly other products, does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity…
ModificadaMedia (4.3)1.3%—Grapecity Data Dynamics Reports10/4/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the DataDynamics.Reports.Web class library in GrapeCity Data Dynamics Reports before 1.6.2084.14 allow remote attackers to inject arbitrary web script or HTML via (1) the reportName or (2) uniqueId parameter to CoreViewerInit.js, or the (3) uniqueId or (4)…
ModificadaAlta (7.5)39%—Quate Grape WEB Statistics25/4/200816/6/2026
PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP code via a URL in the location parameter.